Researchers Compromised One Junior Employee's Inbox. The AI Assistant Did the Rest


New Research
Email Fraud
August 2026  ·  8 min read

In a controlled exercise, a security research team set out to get from an ordinary staff account to the chief executive's mailbox without being caught — using nothing but the AI assistant already built into the email system. The assistant hid the security alerts, mapped the organisation, learned the executive's writing style, found a pending wire transfer, and drafted the message that redirected it. Every step was a legitimate feature working exactly as designed.


Over the past two years, almost every business email system has quietly acquired an AI assistant. It summarises long threads, drafts replies, searches your history in plain English, and sets up rules for you. For most small businesses it appeared as part of a subscription they already paid for — switched on by default, useful immediately, and never once discussed in a security review.

A security research team recently ran a controlled experiment to find out what that assistant does for somebody who isn't you. They gave themselves one starting condition — access to a single ordinary employee's email account — and one goal: reach the chief executive's mailbox and move money, without being detected.

They never wrote malware. They never exploited a software flaw. They used the assistant, in the way it was built to be used, and it helped them at every step.

$247,500

the pending wire transfer the assistant surfaced — and then helped redirect

Asked for a summary of recent financial activity, the assistant returned active invoices, wire transfers and approval workflows within seconds — including one contract payment sitting in the approval queue. No searching, no reading, no guesswork. The information a human attacker would need hours of careful reading to assemble was delivered on request, correctly, immediately, to whoever happened to be holding the account.

The chain, step by step

What makes this worth studying isn't any single clever trick. It's how ordinary each step is, and how the assistant compresses work that used to take an attacker days.

From one junior account to a redirected payment
1
An ordinary employee's account is compromised. This is the hardest part of the whole attack — and, as this series has documented all year, it happens constantly. Everything after this point is downhill.
2
The assistant is asked to set up inbox rules. Sign-in alerts and security notifications get quietly routed to deleted items. The real owner of the account never sees the warnings that would have told them something was wrong. the assistant hides the alarm
3
The assistant is asked about the organisation. Who reports to whom, who handles payments, who talks to whom and how. A mailbox's history is a detailed map of a business, and the assistant reads it far faster than any person could. the assistant does the reconnaissance
4
An internal message goes to the chief executive. It comes from a genuine colleague's real account, so it carries all the trust an internal email carries. The link in it leads to a page that sits invisibly between the executive and the real sign-in.
5
The executive signs in correctly — and the session is captured. Multi-factor authentication is completed properly and still doesn't help, because what gets stolen is the access the successful login produces. Readers of our earlier piece on token theft will recognise this exactly.
6
The same concealment is applied to the executive's mailbox. More rules, more alerts routed away, this time in the account that matters most. the assistant hides the alarm again
7
The assistant is asked to summarise recent financial activity. It returns invoices, transfers and approval workflows — including a substantial contract payment awaiting final approval. Seconds, not hours. the assistant finds the money
8
The assistant drafts the request. A message to the finance team asking to change the destination bank details for that specific payment — written in the executive's own established tone, because the assistant has thousands of examples of it. the assistant writes in the boss's voice
9
Nothing looks wrong. The message comes from the executive's genuine mailbox, references a real transaction the finance team is already expecting, and sounds exactly like them. Conventional email security has nothing to flag.
Count the steps where the assistant did the work: it concealed the intrusion, performed the reconnaissance, located the money, and wrote the fraudulent request in a voice the recipient trusted. One of the researchers described these assistants as capable of becoming unwitting malicious insiders — improving both the quality and the speed of an attack. That's the precise description. Not a hacked tool. A helpful one, helping the wrong person.

Why the assistant can't tell the difference

It's tempting to ask why the assistant didn't refuse. The answer is that from its point of view, nothing unusual happened. It was asked, by a properly authenticated session on an account it belongs to, to do four things it exists to do: manage rules, summarise information, search history, and draft an email in the account owner's style.

There is no step in that sequence where a suspicious request appears. Each one is a feature. The assistant has no way to know that the hand on the keyboard changed — and that is precisely the property attackers exploit. Using a system's own legitimate capabilities rather than bringing your own tools is an old technique with a name in the security world; what's new is how much capability the tool now has.

Here's the part worth sitting with as a business owner: your AI assistant has more comprehensive access to your company's information than almost any individual employee does. It can read every email you've ever received, it knows your suppliers and your payment cycles, it has absorbed how your leadership writes, and it will answer any of that back to whoever is signed in. We have spent a year telling businesses to protect their accounts. Almost nobody has thought about what is now sitting inside them.

Why small businesses are more exposed, not less

A large company has layers of friction that quietly absorb this kind of attack: a finance department with separation of duties, a formal vendor-change process, a security team that reviews new tooling, someone whose job is watching mailbox rule changes. Each layer is a chance for the fraud to surface before the money leaves.

A small business typically has none of those. Payments are frequently handled by one person, who takes instructions directly from the owner, and who has every reason to treat a message from the owner's real address referencing a real invoice as exactly what it appears to be. The AI assistant was enabled by a subscription change nobody reviewed. And there is rarely anyone whose job includes noticing that a mailbox suddenly acquired a rule that deletes security alerts.

Seconds for the assistant to surface invoices, transfers and approval workflows — work that previously meant hours of careful reading Controlled research exercise, 2026
73% of surveyed chief executives said they or someone in their network was affected by cyber-enabled fraud last year World Economic Forum
Zero malware, exploits or software flaws used — every action was a legitimate product feature behaving normally Controlled research exercise, 2026
One important note on fairness: the researchers were explicit that this is not a flaw in one particular product, and that the same approach applies to enterprise AI assistants generally. There is no vendor to blame and no patch to wait for. The capability that makes these tools worth having — broad access to your information, understanding of your context, and the ability to act on instructions — is the same capability that makes a compromised account far more dangerous than it used to be.

Five things to do about it

1

Get alerted when mailbox rules are created

Free · Highest value

Rule creation is the single most reliable early signal in this entire chain, and it happened twice. Attackers hide alerts because they have to — it's the step they can't skip. A business that notices new rules catches this attack in the middle rather than at the bank.

Ask your IT provider today"Do we get alerted when a mailbox rule is created that deletes or moves messages — and who actually reads that alert?" If the answer is no or nobody, that's the highest-value gap you can close this week. Also ask them to review existing rules across all mailboxes now; the ones already there are worth seeing.
2

Make bank detail changes require a phone call — always

Free · Stops the ending

Every version of this attack ends the same way: a request to change where money goes. That request will arrive from a real address, in a real thread, about a real invoice, in a familiar voice. It will pass every instinct you have. The only defence that survives all of that is refusing to act on the message at all.

Write this rule down"Any request to change bank details or redirect a payment is verified by calling the requester on their known number — the one already on file, never a number from the message — before anything is actioned. No exceptions, regardless of who asks or how urgent it sounds." This one rule defeats the entire chain at the last step.
3

Treat the assistant as a privileged asset in its own right

Review · Free

Most businesses have never asked which accounts have an AI assistant enabled, what it can reach, or whether the people with the most sensitive mailboxes need it switched on at all. It should appear in your access reviews alongside admin rights, because functionally that's closer to what it is.

Three questions to answerWhich accounts have an assistant enabled? What data can it reach beyond email — files, calendars, chat? And do the highest-risk mailboxes actually need it? Turning it off for a small number of sensitive accounts is a legitimate and low-cost option.
4

Close the door the executive account came through

Low cost · High value

The pivot to the executive worked by capturing the session after a correct sign-in — the token-theft pattern we covered recently. Codes and push approvals can be relayed in real time; sign-in methods bound to a physical device can't. And when something goes wrong, resetting a password without ending the sessions may change nothing.

PrioritiseMove leadership, finance and administrator accounts to phishing-resistant sign-in first. And make sure whoever manages your systems knows how to revoke active sessions, not just reset passwords — practise it once before you need it.
5

Tell your finance team what this looks like now

Free · One conversation

Traditional training taught people to look for bad grammar, odd addresses and generic greetings. None of those signals exist here. The message is well written, internally sourced, contextually accurate and stylistically perfect. Training that still emphasises spotting fakes is teaching a skill that no longer applies.

The message to send"A payment request can look completely genuine — right person, right address, right invoice, right tone — and still be fraudulent. We don't judge these by how convincing they are. We verify them by phone, every time. You will never be criticised for making that call."
The Veriti Spottr CyberScore's Security Posture assessment covers the controls this chain exploited end to end — mailbox rule monitoring, session and token handling, authentication strength, and the payment verification practices that stop the final step. Our Threat Intelligence feed tracks the account-takeover techniques being used to get that first foothold. The assistant isn't the vulnerability. The account it sits inside is.

The short version

A researcher started with one ordinary employee's inbox and finished with a redirected payment, and the most capable participant in the attack was a tool the business had bought on purpose. No malware. No exploit. No flaw to patch. Just a very good assistant, helping whoever was signed in.

The uncomfortable conclusion is that account compromise now costs a business more than it used to. The same break-in that once bought an attacker a mailbox to read now buys them a research analyst, a ghostwriter and a housekeeper who tidies away the evidence. That raises the value of every control that stops the compromise happening — and the value of the one habit that survives even when everything else fails, which is picking up the phone before money moves.

Find out whether the controls that stop this chain are actually in place in your business.

View the Threat Intelligence feed → Find Out More About Veriti Spottr →
VS
Veriti Spottr Team AI-powered cyber risk clarity for SMBs  ·  veritispottr.com

Comments

Popular posts from this blog

The Hidden Cost of Cybersecurity Inaction for Small Businesses

Small Business Ransomware Protection Guide (2026 Edition)

Your Biggest Cyber Risk Isn't Outside Your Firewall. It's on Your Payroll.